Trojan ZBot – syshost.exe – 055e1e4dea3fce2c4df72febf3473ff9

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan ZBot
Also known as: Trojan Generic, Trojan CI
SHA256: 8f8adfe24946a750ff413c85d1e264ca10f25e82762ee4e530d13b61d6166ce6
SHA1: 69c134017d5463207296ad85cb76dc8808c3eea0
MD5: 055e1e4dea3fce2c4df72febf3473ff9
File size: 302080 bytes

Created files:

%WinDir%\Installer\{D87BFD91-8C8E-A026-9160-330B714025DC}\syshost.exe – Trojan ZBot

Trojan ZBot created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\syshost32: %WinDir%\Installer\{D87BFD91-8C8E-A026-9160-330B714025DC}\syshost.exe
HKLM\System\CurrentControlSet\Services\syshost32\Type: 10000000
HKLM\System\CurrentControlSet\Services\syshost32\Start: 02000000
HKLM\System\CurrentControlSet\Services\syshost32\ImagePath: “%WinDir%\Installer\{D87BFD91-8C8E-A026-9160-330B714025DC}\syshost.exe” /service

Leave a Reply